[Secure Coding] Hijacking accounts using Unicode

Eric H. Christensen sparks at fedoraproject.org
Tue Jul 9 23:25:27 UTC 2013


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

I thought this article was an interesting read.  An interesting attack vector that caught this company off guard.  

http://labs.spotify.com/2013/06/18/creative-usernames/

- -- Eric

- --------------------------------------------------
Eric "Sparks" Christensen
Fedora Project - Red Hat

sparks at redhat.com - sparks at fedoraproject.org
097C 82C3 52DF C64A 50C2  E3A3 8076 ABDE 024B B3D1
- --------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.13 (GNU/Linux)

iQGcBAEBCgAGBQJR3JvkAAoJEB/kgVGp2CYvoPwL/R53Rwx7Th8zd6NPd1UxH4My
ZkjPpwd7VxXBpdtX8nG5g4RNXApwv61jeeSuhB4uTF2BxNMdSAGMo6o/i+eaJfMP
Sw6PbzADJuFvY+n9YuJ0dPPFo0gYsLqdEYpk9GdRdF3rOyhO4+I78z+AfLLGxlvQ
N3DmBFLwDgb/+N7prZwTQvrwPcXai7emaeiFmckXXc6Ps5IOTJWqAJOi2XJSnrkL
Lwa6mGLOHhKmCQc0nk2VjBfpWIAac4HEmZBgcCcFAFn1oRqgZgZNo8zNUbcOpp/6
1VPp4QFJGSpo4KEDw0h2bwPretj7pJ46C3MblwQP4j7TqV9Xj2blCfnj6034hbZj
QRwTCGa92abciC7jXbei4TClrdlLjOD1HlmDZ3MwMzJbmogowcTh9z82/9gawm0U
9BmmU8Wb+M1ThAAqN3DK1TvzCG8y3Khh+9jZXp6QYggzN043gwEmCxv+24Wex7Pm
7vlM+qB5rFkw+E1Ew+vuMOflBdeoLI4E7g1hXOivMg==
=tEIp
-----END PGP SIGNATURE-----


More information about the security mailing list